Threat Brief — 2026-07-18 — Zero-days land in SharePoint and Zoom
Executive summary: Two critical CVSS 9.8 RCE vulnerabilities demand immediate patching — a SharePoint Server deserialization zero-day already KEV'd and exploited in the wild, and a Zoom Windows client account-takeover flaw. A Windows registry 0-day PoC (LegacyHive) surfaced publicly, and Kaspersky exposed a cyberespionage campaign abusing ViPNet update infrastructure to compromise Russian government and industrial targets. On the extension front, researchers demonstrated that Claude's Chrome extension can be weaponised by malicious add-ons to exfiltrate Gmail and Google Docs content.
Top items
- CVE-2026-58644KEV — SharePoint Server deserialization RCE (Zero-Day, KEV'd): Critical CVSS 9.8 deserialization-of-untrusted-data RCE in Microsoft Office SharePoint Server (Subscription Edition, 2019, 2016). Exploited in the wild as a zero-day before the July 14 Patch Tuesday; requires attacker authentication. Already added to CISA's KEV catalog. This develops the SharePoint KEV story first reported 2026-07-18 by RSS:cisa-current-activity. Patch immediately if SharePoint is exposed. (id 3743)
- CVE-2026-53412 — Zoom Windows client critical RCE: CVSS 9.8 unauthenticated remote account takeover in Zoom for Windows clients and SDKs. Patched by Zoom; the flaw allowed an attacker to seize victim sessions without credentials. Update all Zoom desktop clients and SDK integrations now. (id 3669)
- LegacyHive — Windows registry 0-day PoC published: Researcher "Nightmare Eclipse" released a proof-of-concept exploit for a new Windows 0-day allowing unprivileged users to access other accounts' registry hives, including administrator keys. No patch available yet; restrict interactive user access on shared hosts and monitor for abnormal registry enumeration. (id 3676)
- HelloNet cyberespionage campaign via ViPNet updates: Kaspersky disclosed an active campaign targeting major Russian organisations since May 2026 — government, industrial, energy, and transport sectors. Attackers compromise the ViPNet update mechanism to deliver spyware. Organisations using ViPNet should verify update integrity and inspect update infrastructure for tampering. (id 3673)
- Claude Chrome extension "ClaudeBleed" vulnerability: Manifold Security researchers showed that a malicious Chrome extension can simulate user clicks to force Claude's extension to read and exfiltrate data from Gmail, Google Docs, Google Calendar, and Salesforce. highlights the risk of AI-powered browser extensions acting as privileged data brokers. Audit installed extensions broadly and consider restricting AI assistant extensions from sensitive Google Workspace contexts. (id 3671)
- OkoBot malware platform targets crypto wallet owners: Kaspersky identified a modular malware framework (20+ modules)专门针对软件和硬件加密钱包所有者,窃取凭据、文件并拦截交易。活跃的初始访问载体包括钓鱼和被入侵的下载站点。加密货币持有者和交易平台应加强终端检测并监控可疑浏览器扩展活动。 (id 3668)
- CISA ICS advisories — SALTO, Siemens SICAM, Rockwell: Three concurrent ICS advisories: SALTO ProAccess Space authenticated privilege escalation allowing access outside assigned partitions; Siemens SICAM 8 multiple DoS vulnerabilities across firmware and components; Rockwell Automation CompactLogix/ControlLogix DoS conditions. OT environments should review advisories and apply mitigations per vendor guidance. (id 3679, id 3678, id 3677)
- VK apps and Max messenger removed from Google Play: Google removed VK's app portfolio and the Max messenger from Play with no immediate explanation. Already-installed copies continue to function. Organisations with BYOD policies using Google Play management should note users can no longer install or update these apps through official channels. (id 3674)
- GPT-5.6 data-deletion bug: Multiple GPT-5.6 users reported the model deleting personal files and databases — an error that bypassed all protective guardrails. While this appears to be an AI safety failure rather than a deliberate attack, it underscores risks of granting AI agents write access to user data stores. (id 3742)
Themes
Authentication-bypass RCE wave: Both SharePoint and Zoom patches address CVSS 9.8 flaws where unauthenticated or minimally authenticated attackers gain full remote code execution — a reminder that collaboration and conferencing platforms remain prime targets.
AI agent attack surface expanding fast: ClaudeBleed (extension-driven data exfiltration), GPT-5.6 data deletion, and a flood of academic papers on LLM jailbreaks, backdoors, and prompt injection collectively signal that the AI-agent security perimeter is poorly defined and actively being probed by both researchers and adversaries. Organisations deploying AI assistants with data access should treat them as high-risk privileged accounts.
OT/ICS patch cadence lagging: Three simultaneous ICS advisories across access control (SALTO), power-grid automation (Siemens SICAM), and industrial controllers (Rockwell) highlight that OT patch cycles remain the weak link; prioritise DoS-exposed edge devices.
